Critical Zoom flaw allows account takeover

Zoom has published a security update for a newly disclosed critical input-validation vulnerability in Zoom Workplace for Windows. Tracked as CVE-2026-53412, the flaw could allow an unauthenticated remote attacker to take over a Zoom account. It carries a CVSS score of 9.8 and requires no user interaction or existing privileges. Zoom has not published further technical detail on how the attack works. No public exploit code or evidence of active exploitation was known when the advisory was published. Affected products include Zoom Workplace for Windows before version 7.0.0 and Zoom Workplace VDI Client for Windows before versions 7.0.10, 6.6.15 and 6.5.18 in their respective release branches.

What this means for your organisation

A hijacked Zoom account gives access to meeting invitations, recordings and chat logs, and provides a highly credible platform for further internal fraud. Requiring no user interaction means training and vigilance do not help here; deploying the update is the control. Check who actually governs your client versions, too. If users update themselves, this is in practice ungoverned.

Berigo recommends

  • Deploy the update centrally to all Windows clients and verify version numbers rather than trusting that users have updated.
  • Enable automatic updating of the Zoom client wherever you are able to.
  • Bring Zoom, Teams and similar collaboration tools into routine vulnerability management, not just servers and network equipment.
  • Review who in the organisation holds administrator rights in your Zoom tenant.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch